Skip to content
KitploitKITPLOIT
工具博客
提交
工具博客
提交

黑客、渗透测试和网络安全工具,武装您的安全武器库!

Kitploit 是一个黑客、网络安全和渗透测试工具的目录。发现最新的项目更新,查找漏洞、分析系统、自动化测试并加强你的安全。

··订阅源·联系·隐私·© 2026 Kitploit

工具目录

分类

查看所有分类
Loading categories

工具

全部Android安全身份验证与授权云基础设施安全防御工具磁盘取证嵌入式系统安全通用工具危害指标 (IOC) 管理OSINT (开源情报)数据包嗅探与分析密码破解渗透测试框架钓鱼工具权限提升侦察静态分析漏洞扫描器Web漏洞扫描器Wi-Fi审计蓝牙安全容器安全动态分析 (沙盒)加密/解密工具漏洞利用框架身份管理iOS安全物联网安全内存取证网络映射社会工程学OSINT密码攻击Payload生成持久化机制端口扫描静态代码分析 (SAST)威胁源与聚合器漏洞分析Web代理与拦截代码分析DNS和子域名枚举动态代码分析 (DAST)漏洞利用哈希分析IDS/IPS规避冒充工具横向移动移动应用渗透测试网络取证逆向工程RFID/NFC工具SCADA/ICS安全脚本与自动化无服务器安全ShellcodeWeb应用程序漏洞利用API安全测试配置审计数据泄露调试器取证分析信息收集移动取证网络访问控制后渗透利用安全虚拟化钓鱼攻击WAF绕过Web安全模糊测试网络安全隐写术无线安全数据恢复恶意软件分析数字取证硬件黑客密码学CTF渗透测试云安全DevSecOps移动安全隐私保护命令与控制社会工程学硬件安全实用工具与框架硬件与物联网安全秘密检测二进制分析威胁情报身份与访问管理 (IAM)供应链安全身份验证机器学习入侵检测论文与研究错误配置子域名枚举电子邮件收集学习与教育AI 辅助逆向DNS 模糊测试红队事件响应网络爬虫精选资源远程访问工具Shellcode 生成Payload 开发远程访问木马API 安全反机器人指纹欺骗CAPTCHA 绕过电子邮件安全DNS 分析混沌工程学习路径与课程容器逃逸AI 安全数据库安全固件分析异常检测日志分析对抗性攻击二进制利用实验室与实践
最新相关性最受欢迎最近更新
22224 结果
内容在请求的语言中不可用。显示英文版本。
awesome-game-security preview

awesome-game-security

GitHubgmh5225/awesome-game-security

Curated index of game security research: anti-cheat internals, DMA attacks, reverse engineering, kernel/mobile protections, and graphics API hooking…

android-securitydefensive-toolsios-security+8
3.4k
6小时43分前
CVE-2026-8181 preview

CVE-2026-8181

GitHub0xterror/cve-2026-8181

针对 WordPress Burst Statistics 身份验证绕过的漏洞利用 PoC,允许通过精心构造的 Authorization 标头在未经身份验证的情况下冒充管理员。

authentication-authorizationprivilege-escalationvulnerability-analysis+4
1天前
CVE-2026-28134 preview

CVE-2026-28134

GitHubrandomrobbiebf/cve-2026-28134

JetEngine <= 3.7.2 - 已认证(投稿者及以上)远程代码执行

vulnerability-analysisexploitationweb-application-exploitation+1
5个月前
CVE-2025-67923 preview

CVE-2025-67923

GitHubrandomrobbiebf/cve-2025-67923

JetEngine <= 3.7.7 — 通过 CCT REST API 的未认证存储型跨站脚本

vulnerability-analysisexploitationweb-application-exploitation+2
5个月前
CVE-2026-2413 preview

CVE-2026-2413

GitHubrandomrobbiebf/cve-2026-2413

Ally – Web 可访问性与可用性 <= 4.0.3 - 通过 URL 路径的未认证 SQL 注入

vulnerability-analysisexploitationweb-application-exploitation+1
5个月前
CVE-2026-39987 preview

CVE-2026-39987

GitHubk3ystr0k3r/cve-2026-39987

Marimo 预认证 RCE 的概念验证漏洞利用。利用未认证的 /terminal/ws WebSocket 端点生成 PTY 并建立反向 shell。

vulnerability-analysisexploitationweb-application-exploitation+2
1天前
offensive-one-liners preview

offensive-one-liners

GitLabwattocyber/offensive-one-liners

110条用于授权测试和CTF的进攻性安全单行命令,按类别和杀伤链步骤组织在一个Markdown笔记本中。双重用途参考;detection-defense-library中的环境检测与规避检测。

privilege-escalationreconnaissancepassword-attacks+9
3天前
wasm2c-tableflip preview

wasm2c-tableflip

GitHubtrustsig-eu/wasm2c-tableflip

wasm2c 沙箱逃逸。一个不受信任的 WebAssembly 模块突破了生成的 C 沙箱,并在主机上执行任意 shell 命令。

vulnerability-analysisexploitationsecurity-virtualization+1
42天前
CVE-2026-61241 preview

CVE-2026-61241

GitHubgodliveanton/cve-2026-61241

Oracle OID LDAP 服务器权限管理漏洞利用

privilege-escalationexploitationnetwork-security+3
2天前
certighost preview

certighost

GitHubl0u7r3/certighost

CVE-2026-54121 的概念验证利用代码,经过改编和编辑,用于在受影响环境中验证该漏洞。

vulnerability-analysisexploitationpenetration-testing
2天前
halo-cve-2026-67919 preview

halo-cve-2026-67919

GitHubk0nnect/halo-cve-2026-67919

halo cms 插件单请求 RCE(通过 URL),PoC + 漏洞利用链

exploitationweb-application-exploitationweb-security+3
12天前
CVE-2021-42013_821311 preview

CVE-2021-42013_821311

GitHubandreamammano89-maker/cve-2021-42013_821311

在渗透测试期间,利用 Apache HTTP Server CVE-2021-42013 进行路径遍历和基于 CGI 的远程代码执行。

vulnerability-analysisexploitationweb-application-exploitation+1
2天前
CVE-2026-15748 preview

CVE-2026-15748

GitHububaydev/cve-2026-15748

Forminator Forms <= 1.56.1 - 未认证的任意文件上传(通过伪造的上传字段配置)

vulnerability-analysisexploitationweb-application-exploitation+3
2天前
CVE-2026-64849.yaml preview

CVE-2026-64849.yaml

GitHubzavisco/cve-2026-64849.yaml

检测未认证的 MLflow webhook SSRF(CVE-2026-64849),该漏洞可访问内部或云元数据服务,并通过重定向绕过泄露响应详细信息。

vulnerability-scannersexploitationweb-application-exploitation+3
2天前
Apache-OFBiz-Auth-Bypass-and-RCE-Exploit-CVE-2023-49070-CVE-2023-51467 preview

Apache-OFBiz-Auth-Bypass-and-RCE-Exploit-CVE-2023-49070-CVE-2023-51467

GitHubgraysignal/apache-ofbiz-auth-bypass-and-rce-exploit-cve-2023-49070-cve-2023-51467

该漏洞利用工具会扫描所提供的目标是否存在 CVE-2023-49070/CVE-2023-51467 漏洞,并根据用户的选择对其进行利用。

vulnerability-scannersexploitationweb-application-exploitation+3
12年前
CVE_2019_2215 preview

CVE_2019_2215

GitHub0xbinder/cve_2019_2215

针对 Android Binder UAF 的概念验证型 LPE 漏洞利用,通过 iovec 喷射和 addr_limit 覆盖实现任意内核读写。

android-securityprivilege-escalationvulnerability-analysis+5
12天前
CVE-2026-64849 preview

CVE-2026-64849

GitHubbiutrap/cve-2026-64849

CVE-2026-64849 的概念验证漏洞利用程序:通过精心构造的 POST 请求触发 MLflow webhook API 中的 SSRF,从 169.254.169.254 获取云实例元数据。

vulnerability-analysisexploitationweb-application-exploitation+4
2天前
CVE-2024-8068-CVE-2024-8069 preview

CVE-2024-8068-CVE-2024-8069

GitHubhorkimhab/cve-2024-8068-cve-2024-8069

用于 CVE-2024-8068 和 CVE-2024-8069 的 PoC 漏洞利用脚本,专注于授权渗透测试、教学实验室和防御性安全研究。

vulnerability-analysisexploitationpenetration-testing+2
2天前
上一页12…100下一页